Overview
- Poland’s CERT Polska confirmed active exploitation of CVE‑2026‑73570 in mid‑August and urged administrators to hunt for signs of compromise.
- The bug is a command‑injection flaw in Zimbra’s SNMP notification code that lets an unauthenticated attacker send a crafted SMTP request to execute OS commands as the zimbra user.
- Zimbra released a fix in version 10.1.20 on July 20, but internet scans by Shadowserver find roughly 12,100 Zimbra servers reachable online, many of which may still be vulnerable or unpatched.
- CERT Polska published indicators of compromise and tells admins to check /var/log/zimbra.log for unexpected service restarts and recent files owned by zimbra in /opt/zimbra/jetty/webapps/, /opt/zimbra/jetty_base/webapps/, and /tmp/.
- Because past Zimbra bugs have been used by state‑linked and criminal groups to steal mail and credentials, organizations should prioritize patching, limit SMTP exposure, monitor egress traffic, and assume risk until investigations confirm no breach.